des millions d'objets connect\u00e9s menac\u00e9s par une faille dans UPnP, faites d'urgence une mise \u00e0 jour<\/title>\n<meta name=\"description\" content=\"Un chercheur en s\u00e9curit\u00e9 informatique vient de d\u00e9couvrir une faille critique dans le protocole UPnP, qui \u00e9quipe des millions d'appareils \u00e0 travers le monde.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"S\u00e9curit\u00e9 : des millions d'objets connect\u00e9s menac\u00e9s par une faille dans UPnP, faites d'urgence une mise \u00e0 jour\" \/>\n<meta property=\"og:description\" content=\"Un chercheur en s\u00e9curit\u00e9 informatique vient de d\u00e9couvrir une faille critique dans le protocole UPnP, qui \u00e9quipe des millions d'appareils \u00e0 travers le monde.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html\" \/>\n<meta property=\"og:site_name\" content=\"PhonAndroid\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/phonandroid\" \/>\n<meta property=\"article:published_time\" content=\"2020-06-10T17:07:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-06-10T18:07:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wp-pa.phonandroid.com\/uploads\/2020\/06\/faille-protocole-upnp-iot.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"750\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Kevin Dachez\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@phonandroid\" \/>\n<meta name=\"twitter:site\" content=\"@phonandroid\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kevin Dachez\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html\"},\"author\":{\"name\":\"Kevin Dachez\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/3001e437c542c9695c28fcfcf4e69afc\"},\"headline\":\"S\u00e9curit\u00e9 : des millions d’objets connect\u00e9s menac\u00e9s par une faille dans UPnP, faites d’urgence une mise \u00e0 jour\",\"datePublished\":\"2020-06-10T17:07:11+00:00\",\"dateModified\":\"2020-06-10T18:07:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html\"},\"wordCount\":567,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"},\"articleSection\":[\"S\u00e9curit\u00e9\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html#respond\"]}],\"copyrightYear\":\"2020\",\"copyrightHolder\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html\",\"url\":\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html\",\"name\":\"S\u00e9curit\u00e9 : des millions d'objets connect\u00e9s menac\u00e9s par une faille dans UPnP, faites d'urgence une mise \u00e0 jour\",\"isPartOf\":{\"@id\":\"https:\/\/www.phonandroid.com\/#website\"},\"datePublished\":\"2020-06-10T17:07:11+00:00\",\"dateModified\":\"2020-06-10T18:07:53+00:00\",\"description\":\"Un chercheur en s\u00e9curit\u00e9 informatique vient de d\u00e9couvrir une faille critique dans le protocole UPnP, qui \u00e9quipe des millions d'appareils \u00e0 travers le monde.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.phonandroid.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"S\u00e9curit\u00e9 : des millions d’objets connect\u00e9s menac\u00e9s par une faille dans UPnP, faites d’urgence une mise \u00e0 jour\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.phonandroid.com\/#website\",\"url\":\"https:\/\/www.phonandroid.com\/\",\"name\":\"PhonAndroid\",\"description\":\"PhonAndroid\",\"publisher\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.phonandroid.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.phonandroid.com\/#organization\",\"name\":\"PhonAndroid\",\"url\":\"https:\/\/www.phonandroid.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.phonandroid.com\/wp-content\/themes\/phonadroid-v3\/assets\/images\/lg-phonandroid-amp-4.png\",\"contentUrl\":\"https:\/\/img.phonandroid.com\/2023\/06\/dark.png\",\"width\":280,\"height\":60,\"caption\":\"PhonAndroid\"},\"image\":{\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/phonandroid\",\"https:\/\/twitter.com\/phonandroid\",\"https:\/\/www.youtube.com\/user\/Phonandroidtv\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/3001e437c542c9695c28fcfcf4e69afc\",\"name\":\"Kevin Dachez\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/520860d02bb9f0366d858dd41b27739e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/520860d02bb9f0366d858dd41b27739e?s=96&d=mm&r=g\",\"caption\":\"Kevin Dachez\"},\"description\":\"Chef de rubrique Mobilit\u00e9 urbaine et voitures \u00e9lectriques. Entre deux actualit\u00e9s sur les derniers mod\u00e8les watt\u00e9s, j'\u00e9cris \u00e9galement sur mon autre passion : les jeux vid\u00e9o. Remedy, ne ratez pas Alan Wake 2 s'il vous pla\u00eet.\",\"url\":\"https:\/\/www.phonandroid.com\/author\/kdachez\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"S\u00e9curit\u00e9 : des millions d'objets connect\u00e9s menac\u00e9s par une faille dans UPnP, faites d'urgence une mise \u00e0 jour","description":"Un chercheur en s\u00e9curit\u00e9 informatique vient de d\u00e9couvrir une faille critique dans le protocole UPnP, qui \u00e9quipe des millions d'appareils \u00e0 travers le monde.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html","og_locale":"fr_FR","og_type":"article","og_title":"S\u00e9curit\u00e9 : des millions d'objets connect\u00e9s menac\u00e9s par une faille dans UPnP, faites d'urgence une mise \u00e0 jour","og_description":"Un chercheur en s\u00e9curit\u00e9 informatique vient de d\u00e9couvrir une faille critique dans le protocole UPnP, qui \u00e9quipe des millions d'appareils \u00e0 travers le monde.","og_url":"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html","og_site_name":"PhonAndroid","article_publisher":"https:\/\/www.facebook.com\/phonandroid","article_published_time":"2020-06-10T17:07:11+00:00","article_modified_time":"2020-06-10T18:07:53+00:00","og_image":[{"width":1200,"height":750,"url":"https:\/\/wp-pa.phonandroid.com\/uploads\/2020\/06\/faille-protocole-upnp-iot.jpg","type":"image\/jpeg"}],"author":"Kevin Dachez","twitter_card":"summary_large_image","twitter_creator":"@phonandroid","twitter_site":"@phonandroid","twitter_misc":{"Written by":"Kevin Dachez","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html#article","isPartOf":{"@id":"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html"},"author":{"name":"Kevin Dachez","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/3001e437c542c9695c28fcfcf4e69afc"},"headline":"S\u00e9curit\u00e9 : des millions d’objets connect\u00e9s menac\u00e9s par une faille dans UPnP, faites d’urgence une mise \u00e0 jour","datePublished":"2020-06-10T17:07:11+00:00","dateModified":"2020-06-10T18:07:53+00:00","mainEntityOfPage":{"@id":"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html"},"wordCount":567,"commentCount":0,"publisher":{"@id":"https:\/\/www.phonandroid.com\/#organization"},"articleSection":["S\u00e9curit\u00e9"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html#respond"]}],"copyrightYear":"2020","copyrightHolder":{"@id":"https:\/\/www.phonandroid.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html","url":"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html","name":"S\u00e9curit\u00e9 : des millions d'objets connect\u00e9s menac\u00e9s par une faille dans UPnP, faites d'urgence une mise \u00e0 jour","isPartOf":{"@id":"https:\/\/www.phonandroid.com\/#website"},"datePublished":"2020-06-10T17:07:11+00:00","dateModified":"2020-06-10T18:07:53+00:00","description":"Un chercheur en s\u00e9curit\u00e9 informatique vient de d\u00e9couvrir une faille critique dans le protocole UPnP, qui \u00e9quipe des millions d'appareils \u00e0 travers le monde.","breadcrumb":{"@id":"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.phonandroid.com\/une-faille-securite-dans-le-protocole-upnp-menace-des-millions-dobjets-connectes.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.phonandroid.com\/"},{"@type":"ListItem","position":2,"name":"S\u00e9curit\u00e9 : des millions d’objets connect\u00e9s menac\u00e9s par une faille dans UPnP, faites d’urgence une mise \u00e0 jour"}]},{"@type":"WebSite","@id":"https:\/\/www.phonandroid.com\/#website","url":"https:\/\/www.phonandroid.com\/","name":"PhonAndroid","description":"PhonAndroid","publisher":{"@id":"https:\/\/www.phonandroid.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.phonandroid.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/www.phonandroid.com\/#organization","name":"PhonAndroid","url":"https:\/\/www.phonandroid.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.phonandroid.com\/wp-content\/themes\/phonadroid-v3\/assets\/images\/lg-phonandroid-amp-4.png","contentUrl":"https:\/\/img.phonandroid.com\/2023\/06\/dark.png","width":280,"height":60,"caption":"PhonAndroid"},"image":{"@id":"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/phonandroid","https:\/\/twitter.com\/phonandroid","https:\/\/www.youtube.com\/user\/Phonandroidtv"]},{"@type":"Person","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/3001e437c542c9695c28fcfcf4e69afc","name":"Kevin Dachez","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/520860d02bb9f0366d858dd41b27739e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/520860d02bb9f0366d858dd41b27739e?s=96&d=mm&r=g","caption":"Kevin Dachez"},"description":"Chef de rubrique Mobilit\u00e9 urbaine et voitures \u00e9lectriques. Entre deux actualit\u00e9s sur les derniers mod\u00e8les watt\u00e9s, j'\u00e9cris \u00e9galement sur mon autre passion : les jeux vid\u00e9o. Remedy, ne ratez pas Alan Wake 2 s'il vous pla\u00eet.","url":"https:\/\/www.phonandroid.com\/author\/kdachez"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts\/2298788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/users\/110"}],"replies":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/comments?post=2298788"}],"version-history":[{"count":0,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts\/2298788\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/media\/2298794"}],"wp:attachment":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/media?parent=2298788"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/categories?post=2298788"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/tags?post=2298788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}
Le chercheur en s\u00e9curit\u00e9 informatique Yunus \u00c7adirci annonce ce mercredi 10 juin 2020 la d\u00e9couverte d'une faille de s\u00e9curit\u00e9 critique dans le protocole UPnP<\/strong>, pour Universel Plug & Play. Ce protocole permet \u00e0 des objets connect\u00e9s d'interagir facilement entre eux lorsqu'ils sont sur le m\u00eame r\u00e9seau. Con\u00e7u pour \u00eatre utilis\u00e9 sur un r\u00e9seau local (en LAN), le UPnP n'inclut pas d'authentification<\/strong> ou de m\u00e9canisme de v\u00e9rification.<\/p>\n
C'est d'ailleurs pour cette raison que de nombreux constructeurs de TV, de console de jeux, de routeurs, d'imprimantes ou d'objets connect\u00e9s vendent leurs produits avec le protocole UPnP d\u00e9sactiv\u00e9 par d\u00e9faut<\/strong>. Dans ce cas pr\u00e9cis, il revient \u00e0 l'utilisateur de l'activer soi-m\u00eame. Or, selon Yunus \u00c7adirci, cette faille baptis\u00e9e CallStranger<\/strong> se situe justement dans la fonction\u00a0Subscribe<\/em> (S'inscrire en fran\u00e7ais) du protocole.<\/p>\n
Cette vuln\u00e9rabilit\u00e9 peut avoir des cons\u00e9quences multiples. Elle permet \u00e0 un pirate de scanner les r\u00e9seaux internes<\/strong> depuis un appareil vuln\u00e9rable pour ensuite en exfiltrer des donn\u00e9es<\/strong>. Autre possibilit\u00e9, le hacker peut se servir de CallStranger pour enr\u00f4ler un appareil vuln\u00e9rable dans un botnet<\/strong> pour lancer des attaques DDoS.<\/p>\n